aboutsummaryrefslogtreecommitdiff
;;; GNU Guix --- Functional package management for GNU
;;; Copyright © 2020 Jakub Kądziołka <kuba@kadziolka.net>
;;; Copyright © 2020, 2021 Tobias Geerinckx-Rice <me@tobias.gr>
;;; Copyright © 2021 c4droid <c4droid@foxmail.com>
;;; Copyright © 2021 Raghav Gururajan <rg@raghavgururajan.name>
;;;
;;; This file is part of GNU Guix.
;;;
;;; GNU Guix is free software; you can redistribute it and/or modify it
;;; under the terms of the GNU General Public License as published by
;;; the Free Software Foundation; either version 3 of the License, or (at
;;; your option) any later version.
;;;
;;; GNU Guix is distributed in the hope that it will be useful, but
;;; WITHOUT ANY WARRANTY; without even the implied warranty of
;;; MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
;;; GNU General Public License for more details.
;;;
;;; You should have received a copy of the GNU General Public License
;;; along with GNU Guix.  If not, see <http://www.gnu.org/licenses/>.

(define-module (gnu packages cybersecurity)
  #:use-module (guix download)
  #:use-module (guix git-download)
  #:use-module (guix packages)
  #:use-module ((guix licenses) #:prefix license:)
  #:use-module (guix build-system cmake)
  #:use-module (guix build-system python)
  #:use-module (gnu packages cpp)
  #:use-module (gnu packages engineering)
  #:use-module (gnu packages pkg-config)
  #:use-module (gnu packages python)
  #:use-module (gnu packages python-xyz)
  #:use-module (gnu packages python-crypto)
  #:use-module (gnu packages python-web)
  #:use-module (gnu packages time)
  #:use-module (gnu packages bioinformatics)      ;python-intervaltree
  #:use-module (gnu packages emulators))

(define-public blacksmith
  (package
    (name "blacksmith")
    (version "0.0.1")
    (source (origin
              (method git-fetch)
              (uri (git-reference
                    (url "https://github.com/comsec-group/blacksmith")
                    (commit version)))
              (file-name (git-file-name name version))
              (sha256
               (base32
                "0kyp71wndf527dgza5iks5m5vj543mvxp5w7cjd8x0pilmd1xrls"))
              (modules '((guix build utils)))
              (snippet `(begin
                          (delete-file-recursively "external")
                          (substitute* "CMakeLists.txt"
                            (("add_subdirectory\\(external\\)") "")
                            (("[ \t]*FetchContent_MakeAvailable\\(asmjit\\)")
                             (string-append
                              "find_package(asmjit)\n"
                              "find_package(nlohmann_json)")))))))
    (build-system cmake-build-system)
    (arguments
     `(#:tests? #f                      ;no test-suite
       #:imported-modules
       ((guix build copy-build-system)
        ,@%cmake-build-system-modules)
       #:modules
       (((guix build copy-build-system) #:prefix copy:)
        (guix build cmake-build-system)
        (guix build utils))
       #:phases
       (modify-phases %standard-phases
         (add-after 'unpack 'fix-build
           (lambda _
             (substitute* "CMakeLists.txt"
               ;; Use default C++ standard instead.
               (("cxx_std_17") "")
               ;; This project tries to link argagg library, which doesn't
               ;; exist, as argagg project is a single header file.
               (("argagg") ""))))
         (replace 'install
           (lambda args
             (apply (assoc-ref copy:%standard-phases 'install)
                    #:install-plan
                    '(("." "bin" #:include ("blacksmith"))
                      ("." "lib" #:include-regexp ("\\.a$")))
                    args))))))
    (native-inputs
     (list pkg-config))
    (inputs
     (list argagg asmjit nlohmann-json))
    (home-page "https://comsec.ethz.ch/research/dram/blacksmith")
    (synopsis "Rowhammer fuzzer with non-uniform and frequency-based patterns")
    (description
     "Blacksmith is an implementation of Rowhammer fuzzer that crafts novel
non-uniform Rowhammer access patterns based on the concepts of frequency,
phase, and amplitude.  It is able to bypass recent @acronym{TRR, Target Row
Refresh}in-DRAM mitigations effectively and as such can trigger bit flips.")
    (license license:expat)))

(define-public ropgadget
  (package
    (name "ropgadget")
    (version "6.6")
    (source
     (origin
       (method url-fetch)
       (uri (pypi-uri "ROPGadget" version))
       (sha256
        (base32 "08ms7x4af07970ij9899l75sghnxsa7xyx73gkn6gv0l05p1hqfw"))))
    (build-system python-build-system)
    (propagated-inputs
     (list python-capstone))
    (home-page "https://shell-storm.org/project/ROPgadget/")
    (synopsis "Semiautomatic return oriented programming")
    (description
     "This tool lets you search for @acronym{ROP, Return Oriented Programming}
gadgets in binaries.  Some facilities are included for automatically generating
chains of gadgets to execute system calls.")
    (license license:bsd-3)))

(define-public pwntools
  (package
    (name "pwntools")
    (version "4.4.0")
    (source
     (origin
       (method url-fetch)
       (uri (pypi-uri "pwntools" version))
       (sha256
        (base32
         "1qw7j0wwm1878aia08gyw5xljjr26qsbp45w65n4qff672sha5n5"))))
    (build-system python-build-system)
    (arguments
     '(#:tests? #f))                 ;XXX: needs a specific version of unicorn
    (propagated-inputs
     (list capstone
           python-dateutil
           python-intervaltree
           python-mako
           python-packaging
           python-paramiko
           python-psutil
           python-pyelftools
           python-pygments
           python-pyserial
           python-pysocks
           python-requests
           ropgadget
           python-six
           python-sortedcontainers
           unicorn))
    (home-page "https://github.com/Gallopsled/pwntools")
    (synopsis
     "Capture-the-flag (CTF) framework and exploit development library")
    (description
     "Pwntools is a capture-the-flag (CTF) framework and exploit development library.
Written in Python, it is designed for rapid prototyping and development, and
intended to make exploit writing as simple as possible.")
    (license license:expat)))
>Tobias Geerinckx-Rice 2020-01-22gnu: knot-resolver: Install but disable the default managed root TA....* gnu/packages/dns.scm (knot-resolver)[arguments]: Enable 'managed_ta', so 'icann-ca.pem' get installed. Add 'disable-default-ta' phase. 宋文武 2020-01-15gnu: unbound: Update to 1.9.5 [fixes CVE-2019-18934]....The Guix unbound package is not vulnerable in its default configuration, because we do not build with ‘--enable-ipsecmod’. * gnu/packages/dns.scm (unbound): Update to 1.9.5. Tobias Geerinckx-Rice 2019-12-23gnu: nsd: Update to 4.2.4....* gnu/packages/dns.scm (nsd): Update to 4.2.4. Tobias Geerinckx-Rice 2019-12-23gnu: knot: Update to 2.9.2....* gnu/packages/dns.scm (knot): Update to 2.9.2. Tobias Geerinckx-Rice 2019-12-23gnu: knot-resolver: Update to 4.3.0 [fixes CVE-2019-19331]....* gnu/packages/dns.scm (knot-resolver): Update to 4.3.0. Tobias Geerinckx-Rice 2019-12-19gnu: bind: Update to 9.14.9....* gnu/packages/dns.scm (isc-bind): Update to 9.14.9. Tobias Geerinckx-Rice 2019-12-04gnu: knot: Update to 2.9.1 [fixes CVE-2019-19331]....* gnu/packages/dns.scm (knot): Update to 2.9.1. Leo Famulari 2019-12-03gnu: nsd: Update to 4.2.3....* gnu/packages/dns.scm (nsd): Update to 4.2.3. Tobias Geerinckx-Rice 2019-11-20gnu: bind: Update to 9.14.8 [fixes CVE-2019-6477]....* gnu/packages/dns.scm (isc-bind): Update to 9.14.8. Tobias Geerinckx-Rice 2019-11-11gnu: Add knot-resolver....* gnu/packages/dns.scm (knot-resolver): New package. 宋文武 2019-10-29gnu: libasr: Update to 1.0.3....* gnu/packages/dns.scm (libasr): Update to 1.0.3. [arguments]: Replace ‘bootstrap’ and add ‘install-documentation’ phase. [native-inputs]: Add libtool and remove groff. Tobias Geerinckx-Rice 2019-10-27gnu: unbound: Update to 1.9.4....* gnu/packages/dns.scm (unbound): Update to 1.9.4. Tobias Geerinckx-Rice 2019-10-27gnu: libasr: Don't use NAME in source URI....* gnu/packages/dns.scm (libasr)[source]: Hard-code NAME. Tobias Geerinckx-Rice 2019-10-16gnu: bind: Update to 9.14.7 [fixes CVE-2019-6475 & CVE-2019-6476]....* gnu/packages/dns.scm (isc-bind): Update to 9.14.7. Tobias Geerinckx-Rice 2019-10-11gnu: knot: Update to 2.9.0....* gnu/packages/dns.scm (knot): Update to 2.9.0. Tobias Geerinckx-Rice 2019-09-18gnu: bind: Update to 9.14.6 [fixes CVE-2019-6471]....* gnu/packages/dns.scm (isc-bind): Update to 9.14.6. Tobias Geerinckx-Rice 2019-09-17gnu: unbound: Update to 1.9.3....* gnu/packages/dns.scm (unbound): Update to 1.9.3. Tobias Geerinckx-Rice 2019-08-22gnu: nsd: Update to 4.2.2....* gnu/packages/dns.scm (nsd): Update to 4.2.2. Tobias Geerinckx-Rice 2019-08-22gnu: bind: Update to 9.14.5....* gnu/packages/dns.scm (isc-bind): Update to 9.14.5. Tobias Geerinckx-Rice 2019-07-28gnu: unbound: Update to 1.9.2....* gnu/packages/dns.scm (unbound): Update to 1.9.2. Rutger Helling 2019-07-18gnu: bind: Update to 9.14.4....* gnu/packages/dns.scm (bind): Update to 9.14.4. Tobias Geerinckx-Rice 2019-06-20gnu: bind: Update to 9.14.3 [fixes CVE-2019-6471]....* gnu/packages/dns.scm (isc-bind): Update to 9.14.3. Tobias Geerinckx-Rice 2019-06-17gnu: nsd: Update to 4.2.0....* gnu/packages/dns.scm (nsd): Update to 4.2.0. Tobias Geerinckx-Rice 2019-06-17gnu: knot: Update to 2.8.2....* gnu/packages/dns.scm (knot): Update to 2.8.2. Tobias Geerinckx-Rice 2019-05-16gnu: bind: Update to 9.14.2....* gnu/packages/dns.scm (isc-bind): Update to 9.14.2. [source]: Remove patch. [arguments]: Run only fuzz tests. * gnu/packages/patches/bind-fix-unused-pk11-ecc-constants.patch: Delete file. * gnu/local.mk (dist_patch_DATA): Remove it. Tobias Geerinckx-Rice 2019-04-24gnu: Add public-suffix-list....* gnu/packages/dns.scm (public-suffix-list): New variable. Chris Marusich 2019-04-25gnu: bind: Update to 9.12.4-P1 [fixes CVE-2018-5743, CVE-2019-6467]....* gnu/packages/dns.scm (isc-bind): Update to 9.12.4-P1. [source]: Add patch. [inputs]: Add python and python-ply. * packages/patches/bind-fix-unused-pk11-ecc-constants.patch: New file. * gnu/local.mk (dist_patch_DATA): Add it. Tobias Geerinckx-Rice 2019-04-22gnu: nsd: Update to 4.1.27....* gnu/packages/dns.scm (nsd): Update to 4.1.27. Tobias Geerinckx-Rice 2019-04-15gnu: knot: Update to 2.8.1....* gnu/packages/dns.scm (knot): Update to 2.8.1. [source]: Remove patch. * gnu/packages/patches/knot-include-system-lmdb-header.patch: Delete file. * gnu/local.mk (dist_patch_DATA): Remove it. Tobias Geerinckx-Rice